Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

A multinational streaming entertainment company based in Brazil expands operations into the European Union and the United States. During an annual audit, the Chief Information Security Officer (CISO) reviews legal and compliance obligations for managing customer profiles and payment processing environments. Which of the following requirements must the organization implement to satisfy both GDPR and PCI-DSS compliance mandates? (Select TWO.)

  1. Provide technical mechanisms allowing European data subjects to request the erasure of their personal information within statutory timeframes.Answer
  2. Restrict system access to cardholder data strictly to personnel whose specified job functions require such access.Answer
  3. C
    Deploy network perimeter firewalls as the primary control to prevent application-level memory buffer overflow exploits.
  4. D
    Classify routine application log maintenance as a preventive physical control within the governance baseline.

Answer

The organization must implement mechanisms to honor data erasure requests under GDPR and restrict cardholder data access strictly based on business need-to-know under PCI-DSS.
Enabling mechanisms for users to request data deletion fulfills GDPR data subject rights for personal data, while restricting cardholder data access to job-related duties satisfies PCI-DSS access control rules.

Step-by-Step Solution

1
Identify the privacy obligations required when processing European subscriber data.
GDPR mandates recognizing data subject rights, specifically providing mechanisms to fulfill user requests for data erasure.
Compliance with international privacy frameworks requires respecting the legal rights of data subjects in applicable jurisdictions.
2
Identify technical controls mandated for credit card payment processing environments.
PCI-DSS requires restricting access to cardholder data strictly to authorized users with a defined business need.
Industry standards governing cardholder data mandate enforcing principle of least privilege and strict access controls.
3
Analyze distractors for misclassified control types or ineffective vulnerability mitigations.
Network firewalls do not resolve software buffer overflow flaws, and log auditing is a technical detective control rather than a physical preventive control.
Proper compliance management requires matching appropriate security control types to their correct risk scenarios.

Key Concept

Regulatory Compliance and Legal Requirements Management
Rate this question